TESTforge42's picture
Upload folder using huggingface_hub
9bd79ab verified
|
Raw
History Blame Contribute Delete
1.18 kB
metadata
license: apache-2.0
tags:
  - security-research
  - huntr
  - model-file-security
  - scanner-bypass
  - numpy

picklescan & ModelScan bypass: object-dtype .npy INT-opcode desync (non-pickle container)

Benign security-research PoC for the huntr Model File Format program. Payload only writes a nonce marker (echo) — no real harm.

Vulnerability

A valid object-dtype NumPy .npy embeds a pickle stream that ModelScan scans via its numpy-specific path (NumpyUnsafeOpScan) and picklescan via its numpy handling. The embedded pickle carries the INT-opcode desync prefix (I0x10\n): genops parses base-10 and aborts before the payload, while numpy.load(allow_pickle=True) parses 0x10 base-0 and executes the reduce payload. Defeats the numpy-SPECIFIC defence that CATCHES a plain malicious object .npy — a distinct code path and format ($1500 non-pickle tier).

Measured (2026-07-24): picklescan 1.0.5 exit 0; ModelScan 0.8.8 no issue; numpy.load fires the benign marker.

Reproduce

import numpy as np
np.load("model.npy", allow_pickle=True)   # fires the benign marker at load
picklescan -p model.npy   # exit 0
modelscan -p model.npy     # no issue